Founder of Nano Labs X was stolen: AI became the breakthrough point.

CN
2 hours ago

Nano Labs founder and chairman Jack Kong (孔剑平, hereinafter referred to as Jack Kong) encountered a seemingly "traditional," yet highly untraditional cyber attack in the autumn of 2026: his X account was phished and regained control within a short period. The starting point of the attack was not concealed—an ordinary account verification email sent to his publicly available email; the real danger lay in the link within the email, which, after being analyzed by his AI assistant, was judged to be a "trustworthy, nearly official verification page." Under this erroneous "endorsement," Jack Kong clicked on the phishing site disguised as the X verification page and entered the real verification code sent by the X platform to his linked email, effectively handing over the key credentials needed to take over the account to the attacker. Subsequently, the attacker successfully logged in and briefly controlled the social voice of the founder of a publicly listed crypto treasury company related to the BNB ecosystem in the U.S., using the account to publish false projects or scam promotion content unrelated to Nano Labs' business, misleading users in the circle who habitually regard the founder's account as an "official signal source." As of 2026-09-28, Jack Kong has confirmed that the X account is back under his control, with several Chinese crypto media outlets such as PANews, 深潮 TechFlow, BlockBeats, and Foresight News reporting on this development; however, there is currently no authoritative verification of the attack duration, the amount involved, or specific token names and other quantitative details. The greatest shadow left by the incident is rather the successfully deceived judgment of the AI assistant and the new trust gaps it exposed in the entire attack chain.

Phishing email and AI negligence: how the attack chain came together

It all began with a system notification email sent to a publicly used email address. The attacker first obtained the email address used by Jack Kong for external communication and packaged the phishing content as an update related to the X account verification process or a security alert, leaving only a link in the body to "complete verification." Before clicking, Jack Kong normally passed the email and link to his AI assistant for initial screening—this is the "safety net" that many founders' high-frequency publicly exposed accounts rely on. But this time, the AI was deceived by the pre-deployed disguise: the page linked in the malicious link intentionally mimicked X's official or trusted third-party verification page in layout, icon colors, and tone, leading the AI to give a "trustworthy" and "similar to official verification process" judgment after a superficial comparison.

On this false "endorsement," the human alert defense line clearly softened. After clicking into the disguise page, the interface required him to complete what seemed like a standard security verification: the X platform would send a verification code to his linked email, which he only needed to input on the page to confirm. Up to this point, X's real security process was still functioning normally— the verification code was indeed sent from the official system to the correct linked email, designed to appear only in the channel between the user and the official. However, bolstered by the AI's security judgment, Jack Kong input this real verification code, which should only have been entered into the official X end, into the attacker's carefully disguised "verification box." This action equated to actively handing the necessary key credentials for taking over the account to the other party. Subsequently, the attacker successfully controlled Jack Kong's X account using the verification code or related login credentials, publishing multiple false projects or scam promotion content unrelated to Nano Labs' business as the founder, while what truly deserves vigilance is that the entire attack chain has now successfully demonstrated the path of "first deceiving AI, then deceiving real people."

The moment the security consultant became a breach tool

In this story, the "gatekeeper" role was not assigned to a security manager, but to an AI assistant that seemed omniscient. After the phishing email reached Jack Kong's public email, the first review was no longer conducted by him, but entrusted to the model: asking it to judge whether the email was trustworthy and whether the link was safe. In such a process, it is natural for people to treat AI as a "security consultant"—since they have already "consulted a professional," they subconsciously let their guard down, treating originally suspicious details that would have been scrutinized as negligible noise.

The problem is that the "professional" being treated as a consultant was never born for security auditing. General AI models are primarily designed to understand and generate text, making their responses appear coherent, rational, and like someone "in the know," rather than systematically identify deception patterns or perform risk isolation like professional anti-phishing systems. In this incident, the AI assistant was not only asked to give a "safe/unsafe" judgment but was mistakenly trusted to have sufficient understanding of the X official process, resulting in the malicious link disguised as "account verification" being classified as "official verification" or a trusted page. In recent years, such phishing pages disguised as account verification or KYC processes have become common in social platform attacks, and this time, the attacker first successfully deceived the AI, then used the AI's erroneous "endorsement" to alter real people's decisions: when Jack Kong chose to trust the model, the last line of security verification that originally belonged to humans effectively ceased to exist. For executives in the crypto industry, when they become accustomed to using AI to handle the complex information flow, filter notifications, and links, the responsibility for security has, unknowingly, become blurred or even outsourced, until one day, this outsourced "responsibility" turns into a tool for attackers to break in.

Founder account hijacked: how false projects harvest trust

For many, Jack Kong's X account itself is a form of "quasi-official announcement." In a crypto treasury company listed in the U.S. and related to BNB, the personal account of the founder and chairman plays the role of communicating business progress, partnership directions, and market judgments. Founder-level social accounts already carry powerful trust endorsements and market influence in the crypto industry, and long-term investors, partners, and even ordinary speculators who follow Nano Labs instinctively treat this account as the "first entry" for filtering information. Because of this, once the avatar and ID remain unchanged, and the tone seems normal, most people find it hard to realize at first that the speaker has already been replaced by the attacker.

During the time the account was under control, the attacker targeted this trust dividend, leveraging Jack Kong's identity as a credit endorsement, continuously posting false projects or obviously scam-laden promotional information unrelated to Nano Labs' actual business, guiding users to pay attention, share, and even participate in projects of uncertain origins. In terms of information format, this content was no different from common "founder announcing new plans" or "participating in community airdrop" activities, sufficient to let ordinary users, who are accustomed to relying on major accounts for opportunities, relax their vigilance. Although there is currently no reliable public information indicating that specific users suffered exact financial losses due to this false information, during the window of the attack, anyone who mistakenly treated this content as an official action was objectively exposed to a high risk.

For Nano Labs, this incident first tore apart the margins of its own credibility: when the founder's account was used to push information about projects unrelated to the company's business, even if control has been regained and clarified afterward, some external observers may find it hard to completely erase the moment of doubt. Partners need to reassess whether, when cooperating with such a crypto treasury company related to BNB, they need to raise the threshold for information verification and announcement confirmation; from a broader narrative perspective of the BNB ecosystem, a case where a "founder account of an ecological company was used to promote scam projects" could also be amplified by competitors to question the entire ecosystem's maturity in terms of security governance and executive account protection. However, as of now, there is no verified data to support a direct link between the incident's impact on Nano Labs' stock price, BNB price, or other asset performance; this impact remains more at the level of trust discount and risk perception, still awaiting time and subsequent governance practices to repair and verify.

Locking both AI and accounts: a self-protection checklist for executives

If this incident is viewed as a reverse teaching material, the "minimum configuration" for account security for executives in crypto companies is actually not complex. The first layer is traditional account protection: enabling two-factor authentication for all high-value social accounts and associated emails uniformly, prioritizing hardware security keys over SMS verification codes that are easier to hijack; secondly, separating the emails associated with these accounts from daily public email addresses, using a separate internal-only address to reduce the attack surface, like in this incident, where the public email was phished leading to the “entire account chain being implicated.” Further down, a bottom line that security experts repeatedly emphasize is that any verification codes, private keys, mnemonic phrases, and other sensitive information should never be entered into unidentified web forms or third-party tools; in this incident, the real verification code being input into the disguised page rather perfectly illustrates that verification codes themselves are not an all-powerful talisman; once entered incorrectly, they become a key to open doors instead of a firewall.

The second layer is to draw a "security red line" for the AI itself. In industry discussions, a consensus is forming: AI can help read emails, translate terms, and assist in streamlining processes, but for any critical actions involving inputting verification codes, confirming logins, on-chain signatures, etc., AI should not provide affirmative suggestions like "looks fine" or "you can continue operating," nor should AI decide whether to execute. Executives need to make it clear at the team level: AI is responsible only for highlighting risks and listing options, while humans are responsible for the final action. Lastly, there should also be an organizational-level insurance—an emergency SOP should be pre-established for the social accounts of the founder and core executives: once capture is detected, who will be responsible for releasing a "the account has been breached" announcement using which channels in the first instance, how to centrally clarify abnormal content and unify external statements, compressing the secondary harm of false projects or scam promotions posted during the hijacked period within the shortest time window, thereby minimizing the long-term discount to the company's and users' trust from a security incident.

This is not an isolated incident but a turning point for AI security

If there is anything truly chilling about this incident, it is not that Jack Kong's X account was once under control but has since been restored as of 2026-09-28, nor is it that there is currently no solid evidence showing large-scale financial losses, but rather that the attack chain has for the first time clearly written a new note: the AI assistant has been formally incorporated into the security decision-making process and has been successfully utilized by attackers. The attacker did not directly persuade the founder, but first deceived the AI, which then "reiterated" a seemingly professional and rational security conclusion, thereby gaining trust at the moment of entering the verification code. This implies that in the crypto industry, which heavily relies on founders' social accounts to convey key information, AI is rapidly becoming a "trusted intermediary that can be exploited"—it screens emails, evaluates links, and offers advice, but also inadvertently certifies phishing pages. As more high-value targets embed AI tools into their workflows, future attackers will likely design scripts systematically around the "human-AI" trust boundary, studying how individuals can be persuaded and under what conditions AI will give incorrect "safe" judgments. What truly needs to be upgraded early is not just verification codes, keys, or SOPs, but the entire threat model of the industry: at the same time as "AI improves efficiency," the considerations of "how to escalate risks when AI is compromised" must also be included in security design; otherwise, the next similar phishing script may not simply be a timely warning case but could become an irreparable collective trust disaster.

Join our community to discuss together and grow stronger!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink